Developer Platform Privacy Policy
_Updated 13 September 2026_
This policy describes the developer platform at developers.dvaarik.com and api.developers.dvaarik.com. It does not describe the separate Dvaarik business application.
Data we process#
Account and security data: name, email, company details you provide, password hash, verification and terms records, account status, access events, and abuse/security signals.
Projects and machine credentials: project configuration, limits, API-key prefixes, scopes, hashes, use timestamps, and revocation state. Project-key plaintext is returned only at creation and is not stored by Dvaarik.
Provider connections: provider name, capabilities, status, masked hint, revision, and encrypted credential material. Credential values are not returned after save. Disconnecting stops active use; minimum audit metadata may remain.
Usage and delivery data: session timing, connected seconds, frozen provider and rate identifiers, exact cost, statuses, errors, idempotency records, webhook attempts, and event metadata when those resources are enabled.
Content: audio, transcripts, prompts, messages, media, tool inputs/results, and webhook bodies may pass through the service and the providers you configure. The applicable API resource describes whether content is transient, retained by a setting, or required for durable delivery. Do not include unnecessary personal data in free-form metadata.
Call audio. Dvaarik does not store call audio. When an agent enables record_calls, Dvaarik asks your carrier to record the call; the recording is created and held in your own carrier account under your own agreement with that carrier. Dvaarik stores only the carrier's reference to the recording so that you can retrieve the audio from your carrier with your own credentials. A browser call has no carrier in the path, so no recording is created.
Transcripts. When store_transcript is enabled, the transcript is stored in the Dvaarik database for 90 days and is then deleted. The short post-call insight summary produced by insight_config is retained on the call record after the transcript is deleted, because it is a small business record of the call. It is generated on the model in your own provider account.
This release is voice only. Webhook signing secrets and agent webhook secrets are shown once at creation and stored encrypted. Dead-letter records keep the delivery id, event name, attempt count, and last error, never the payload. Carrier credentials are stored only after the carrier has accepted them.
Browser storage and analytics#
The console stores account access and rotating refresh tokens in localStorage so you remain signed in. Signing out removes them. Project API keys and provider credentials are not stored there. A theme preference may also be stored.
This site does not load advertising or product-analytics scripts. Operational server logs and error reports are still used for reliability and security.
Who processes data#
Dvaarik uses infrastructure and service subprocessors that may include Railway (hosting and databases), Cloudflare (storage and delivery where enabled), Resend (email), Sentry (error reporting), and Razorpay (payments where enabled).
Your selected AI and telephony accounts are customer-directed providers. We send them only the data needed for the capability you configure. Their own contracts determine their processing and charges; Dvaarik does not silently send work to an unselected shared provider account.
Retention#
Account, project, credential audit, security, and billing records are retained for the active account and then for the period needed for security, disputes, and legal or accounting obligations. Revoked key hashes and delivery idempotency records may remain to prevent replay and explain historical usage.
Content retention follows the specific API resource and project setting. Where a resource offers deletion or a retention window, that contract controls future records; historical financial totals and content-free audit facts may survive content deletion. External providers may retain data under their own terms.
Call transcripts are retained for 90 days from the call and are then deleted; retention_days cannot extend a transcript beyond that window. The post-call insight summary survives the transcript. Call audio is not retained by Dvaarik at all — recordings live in your own carrier account, subject to that carrier's retention terms, and Dvaarik keeps only the reference needed to fetch them.
Refresh tokens expire or are invalidated through rotation, sign-out, and account controls. Encrypted provider tokens are used only while their connection is active and authorized.
Purpose and legal basis#
We process data to provide the contracted service, secure accounts, enforce limits, meter usage, deliver events, prevent abuse, support customers, and meet legal obligations. We do not sell personal data or use customer content for advertising.
International processing#
Provider and infrastructure regions vary. By selecting a provider or carrier, you direct the associated transfer. Review that provider's region and terms for your own application and end users.
Your responsibilities and choices#
Use separate projects, issue narrow scopes, keep machine keys server-side, and provide notices or obtain consent required for your callers and message recipients. You can revoke keys and disconnect provider accounts in the console.
Contact dev@dvaarik.com to request access, correction, closure, or deletion of personal data, subject to identity verification and records we must retain.
Security#
Traffic uses TLS. Passwords and API keys are stored as one-way hashes; provider credentials are encrypted with versioned keys. Authorization is checked against the account and project on every protected resource. No system is risk-free, so report suspected credential exposure promptly and rotate the affected secret.
Changes#
We will update the date above for material changes and provide notice where required.